We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Compliance
  2. EU AI Act compliance
EU AI Act readiness, UAE

The AI Act applies where the output is used in the Union. Your servers being in Dubai does not help.

Article 2 covers providers and deployers established in a third country where the output produced by the AI system is used in the Union. Prohibitions and AI literacy have applied since 2 February 2025, and the general application date is 2 August 2026.

Book an AI Act exposure reviewSee what applies when
EU AI Act readiness for UAE organisations
  • 2 Feb 2025Prohibitions and AI literacy already apply
  • 2 Aug 2026The general application date
  • 8 prohibitionsListed in Article 5(1)
  • Third countryExplicitly in scope under Article 2
The scope test people get wrong

Ask where the output is used, not where the company is registered.

Article 2 was drafted specifically to prevent the obvious avoidance, and it is the reason UAE companies with no EU entity are still in scope.

  • The provision at Article 2(1)(c) covers providers and deployers that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union. Location of the company, the servers and the model are not the test.
  • A UAE company that screens CVs for a client with EU operations, generates content published to EU audiences, or scores applications used by an EU business is producing output used in the Union, whatever the contract says about governing law.
  • Article 2(1)(a) separately covers providers placing AI systems on the market or putting them into service in the Union, and placing general-purpose AI models on the Union market, irrespective of whether established in the Union or in a third country.
  • The practical exercise is short. List your AI systems, and for each one ask where the output ends up. Any answer involving the Union puts that system inside a scope question worth taking seriously rather than assuming away.
Ask us to run the scope test
What the Act actually says

Eight things a UAE organisation needs to establish.

The AI Act is a regulation rather than a directive, so it applies directly across the Union. What brings a UAE company into it is not where the company sits but where the output of its AI system is used.

Third country establishment is explicitly covered

Article 2 applies to providers placing AI systems on the market in the Union irrespective of whether they are established in the Union or in a third country, and to providers and deployers located in a third country where the output produced by the AI system is used in the Union.

It arrives in stages, and two have passed

Prohibitions and AI literacy have applied since 2 February 2025. General-purpose AI and governance provisions since 2 August 2025. The general application date is 2 August 2026, and the Article 6(1) high-risk classification rules apply from 2 August 2027.

Eight practices are prohibited outright

Manipulative or subliminal techniques, exploitation of vulnerabilities by age, disability or social or economic situation, social scoring, predicting criminal offences solely from profiling or personality traits, untargeted facial image scraping, workplace and education emotion inference, sensitive biometric categorisation, and real-time remote biometric identification for law enforcement.

AI literacy is an obligation, not a suggestion

Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and other persons dealing with the operation and use of AI systems on their behalf. It has applied since February 2025 and is frequently missed.

People must be told they are talking to an AI

Providers must ensure AI systems intended to interact directly with natural persons are designed so those persons are informed they are interacting with an AI system, unless this is obvious. That covers chat interfaces, voice agents and support automation.

Synthetic output must be machine-readable marked

Providers of systems generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. That is a product engineering requirement rather than a policy statement.

Deep fakes and public interest text need disclosure

Deployers generating or manipulating image, audio or video constituting a deep fake must disclose that the content has been artificially generated. The same applies to text published to inform the public on matters of public interest.

Emotion and biometric systems require notice

Deployers of an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it of the operation of the system, in a clear and distinguishable manner at the latest at the time of first interaction or exposure.

The timeline

What applies from when.

Taken from Article 113. Two of these dates have already passed, which is why the Act is a present obligation rather than a 2026 planning item.
ProvisionsApplies from
Chapters I and II, prohibitions and AI literacy2 February 2025
General-purpose AI, governance, Chapter III Section 42 August 2025, excluding Article 101 penalties
The Regulation generally2 August 2026
Article 6(1) high-risk classification2 August 2027
Entry into forceTwentieth day after Official Journal publication
Prohibited practices under Article 5Already in force since February 2025
Article 4 AI literacy dutyAlready in force since February 2025
Article 50 transparency dutiesWith the general application date
How we approach it

Four things that keep an AI Act response grounded.

This is a long regulation with a lot of commentary around it. The parts that create immediate exposure for a UAE business are narrow and identifiable.

We screen for prohibitions first

Because they have applied since 2 February 2025 and there is no compliance path for them. A system that infers emotions in a workplace or scrapes facial images without targeting is not a documentation problem, and finding that out early matters more than anything else.

We apply the scope test as written

Providers and deployers in a third country are covered where the output produced by the AI system is used in the Union. We test each system against that wording rather than against where the company or the infrastructure happens to be located.

We treat AI literacy as the quick win it is

Article 4 requires measures to ensure a sufficient level of AI literacy among staff operating AI systems, taking account of their knowledge, the context of use and the people affected. It is already in force, it is achievable quickly, and it is commonly missed entirely.

We separate the Act from voluntary frameworks

A governance framework helps you meet the Act and does not discharge it. Conversely the Act does not give you a governance framework. Knowing which of the two a customer, board or regulator is actually asking about prevents a lot of wasted effort.

How an engagement runs

Four phases across roughly eight to fourteen weeks.

The screening work is fast and it is the part with immediate legal consequence. Transparency engineering and high-risk preparation take longer because they touch the product.
  1. 01
    Weeks 1 to 2

    Scope and prohibition screening

    Every AI system listed, with where its output is used. Then each screened against the eight prohibited practices in Article 5, which have applied since 2 February 2025 and admit no compliance route. That screening is the immediate priority.

    • AI system inventory with output destinations
    • In scope determination per system under Article 2
    • Article 5 prohibition screening completed
    • Any prohibited practice escalated immediately
  2. 02
    Weeks 3 to 5

    Role and AI literacy

    Whether you are a provider, a deployer, an importer or a distributor for each system, since the obligations differ. Then the Article 4 duty to ensure, to your best extent, a sufficient level of AI literacy among staff operating those systems.

    • Role determined per system
    • AI literacy programme scoped by role and context
    • Training delivered and completion recorded
    • Authorised representative question addressed where relevant
  3. 03
    Weeks 6 to 10

    Transparency obligations

    Disclosure that a person is interacting with an AI system, machine-readable marking of synthetic output, deep fake disclosure and public interest text disclosure, and notice for emotion recognition or biometric categorisation systems.

    • Interaction disclosure implemented where not obvious
    • Machine-readable marking of synthetic output specified
    • Deep fake and public interest text disclosure in place
    • Accessibility of the disclosures verified
  4. 04
    Weeks 11 to 14

    High-risk assessment and governance

    Whether any system falls into the high-risk classification, whose rules under Article 6(1) apply from 2 August 2027, and the governance that keeps the position current as systems and their uses change over time.

    • High-risk exposure assessed per system
    • Documentation approach agreed where applicable
    • Change control so new uses are re-screened
    • Board and customer reporting position established
Where this comes up

Six situations that put a UAE business in scope.

None of these involve having an EU entity. All of them involve output that ends up being used in the Union.

A Dubai company screening candidates for EU employers

The system runs in the UAE and the output, a ranking or a shortlist, is used by an employer in the Union. That is output produced by the AI system used in the Union, which is the Article 2(1)(c) test in its plainest form.

A software vendor with a chat assistant in the product

Where the product is used by customers in the Union, providers must ensure people are informed they are interacting with an AI system unless it is obvious. That is an interface requirement, and it is far cheaper to build than to retrofit.

An agency generating content for European audiences

Synthetic audio, image, video or text must be marked in a machine-readable format and detectable as artificially generated. Deep fakes require disclosure, as does text published to inform the public on matters of public interest.

An organisation using emotion analytics on staff

Inferring emotions of a natural person in the areas of workplace and education institutions is a prohibited practice, subject to a medical or safety exception. Where any part of that touches the Union, this is not a risk to manage but a practice to stop.

A firm scoring customers or applicants

Social scoring based on social behaviour or inferred personal characteristics leading to detrimental treatment is prohibited, and predicting criminal offences solely from profiling or personality traits is prohibited. Scoring systems need careful reading against both.

A group with an EU parent asking questions

Group compliance functions have been asking since early 2025, because prohibitions and AI literacy applied from 2 February 2025. A UAE entity that cannot describe its AI systems is a gap in the group answer rather than a local matter.

Three positions

How UAE organisations are treating the AI Act.

The right column is the most common and it rests on a misreading of the scope article, which is the single most consequential mistake available here.
Prohibited practice screening done
Screened and evidencedYes
Waiting for August 2026Not yet
Assumed out of scopeNo
Prohibitions already in force
Screened and evidencedUnderstood
Waiting for August 2026Overlooked
Assumed out of scopeOverlooked
AI literacy obligation met
Screened and evidencedDelivered and recorded
Waiting for August 2026Planned
Assumed out of scopeUnknown
Scope test applied correctly
Screened and evidencedOutput based
Waiting for August 2026Partially
Assumed out of scopeEstablishment based
Interaction disclosure implemented
Screened and evidencedYes
Waiting for August 2026Designed
Assumed out of scopeNo
Synthetic output marking
Screened and evidencedSpecified
Waiting for August 2026Considered
Assumed out of scopeNot considered
Answer for an EU customer
Screened and evidencedDocumented
Waiting for August 2026In progress
Assumed out of scopeNone
Exposure if a prohibition applies
Screened and evidencedIdentified early
Waiting for August 2026Discovered late
Assumed out of scopeDiscovered by somebody else
Effort to reach position
Screened and evidencedWeeks
Waiting for August 2026Deferred
Assumed out of scopeNone
Suitable for a company with EU output
Screened and evidencedYes
Waiting for August 2026Risky
Assumed out of scopeNo
Feature
Screened and evidenced
Waiting for August 2026
Assumed out of scope
Prohibited practice screening done
YesNot yetNo
Prohibitions already in force
UnderstoodOverlookedOverlooked
AI literacy obligation met
Delivered and recordedPlannedUnknown
Scope test applied correctly
Output basedPartiallyEstablishment based
Interaction disclosure implemented
YesDesignedNo
Synthetic output marking
SpecifiedConsideredNot considered
Answer for an EU customer
DocumentedIn progressNone
Exposure if a prohibition applies
Identified earlyDiscovered lateDiscovered by somebody else
Effort to reach position
WeeksDeferredNone
Suitable for a company with EU output
YesRiskyNo
Article 5 screening

Eight questions that must all be answered no.

These are the prohibited practices. Unlike the rest of the Act there is no compliance path, no documentation route and no risk mitigation. The system either does this or it does not.

Manipulation and vulnerability

  • Does it use subliminal or deceptive techniques?
    Article 5(1)(a).
  • Does it exploit age, disability or hardship?
    Article 5(1)(b).
  • Does it score people socially?
    Article 5(1)(c).

Profiling and biometrics

  • Does it predict criminality from profiling alone?
    Article 5(1)(d).
  • Does it scrape facial images untargeted?
    Article 5(1)(e).
  • Does it infer emotions at work or in education?
    Article 5(1)(f).

Sensitive inference

  • Does it infer race, beliefs or sexual orientation?
    Article 5(1)(g).
  • Real-time biometric identification in public?
    Article 5(1)(h).
How an engagement runs

Five steps, in the order that risk actually arrives.

Prohibitions first because they are already in force. Everything else follows a timeline you can still plan around.
  1. 1

    Inventory AI systems and where their output goes

    The scope test at Article 2(1)(c) turns on whether the output produced by the AI system is used in the Union. That means the inventory needs a destination column, and it needs to include systems embedded in products as well as ones built in house.

  2. 2

    Screen every system against Article 5

    The eight prohibited practices, which have applied since 2 February 2025. There is no compliance route for these, so identifying one is an immediate escalation rather than an item on a remediation plan with a date attached to it.

  3. 3

    Establish your role for each system

    Provider, deployer, importer or distributor, since obligations differ by role and a single organisation is frequently more than one across its portfolio. Authorised representative requirements are considered here where they arise.

  4. 4

    Deliver the AI literacy obligation

    Measures to ensure, to your best extent, a sufficient level of AI literacy among staff and others operating AI systems on your behalf, taking into account their knowledge, experience, training, the context of use, and the people the systems are used on.

  5. 5

    Build the transparency and high-risk position

    Interaction disclosure, machine-readable marking of synthetic output, deep fake and public interest text disclosure, and notice for emotion recognition and biometric categorisation. Then the high-risk assessment ahead of the August 2027 classification date.

Straight answers

What UAE organisations ask about the EU AI Act.

Not necessarily. Article 2 applies to providers and deployers with their place of establishment in a third country where the output produced by the AI system is used in the Union. Where your output is used is the test, not where you are established.

It already has, in part. Prohibitions and AI literacy applied from 2 February 2025 and general-purpose AI and governance provisions from 2 August 2025. The general application date is 2 August 2026, with high-risk classification from 2 August 2027.

Eight practices, including subliminal or manipulative techniques, exploiting vulnerabilities by age, disability or social or economic situation, social scoring, predicting criminality solely from profiling, untargeted facial image scraping, workplace and education emotion inference, sensitive biometric categorisation, and real-time public biometric identification for law enforcement.

Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy of staff and others operating AI systems on their behalf, taking account of their technical knowledge, experience, education, training, the context of use, and the persons the systems are used on.

Where the system is intended to interact directly with natural persons, providers must ensure it is designed so those persons are informed they are interacting with an AI system, unless this is obvious. The information must be clear, distinguishable and accessible.

Providers of systems generating synthetic audio, image, video or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. That is an engineering requirement in the product rather than a label in a policy.

Your role determines your obligations. Buying a system generally makes you a deployer rather than a provider, and deployers carry their own duties, including disclosure for deep fakes, notice for emotion recognition and biometric categorisation, and AI literacy.

Deployers of systems generating or manipulating text published for the purpose of informing the public on matters of public interest must disclose that the text has been artificially generated or manipulated. Ordinary marketing copy is not the target of that provision.

Inferring emotions of a natural person in the areas of workplace and education institutions is listed as a prohibited practice, with an exception for medical or safety purposes. Given the exception is narrow, a deployment of this kind needs legal review rather than a risk assessment.

The classification rules at Article 6(1) apply from 2 August 2027 and the categories are set out in the Act annexes. The assessment is worth doing now for systems touching employment, credit, education, essential services or safety, because preparation takes time.

They are separate instruments with overlapping subject matter. GDPR governs personal data processing, the AI Act governs AI systems and their risks. A system can comply with one and breach the other, so both need testing rather than assuming one covers the other.

No. A voluntary framework helps you meet the obligations and is not a substitute for them. Equally the Act does not give you a governance framework, so most organisations end up needing both, applied to the same inventory of systems.

List your AI systems with where their output is used, then screen them against the eight prohibited practices. Both are quick, and both address obligations that have been in force since February 2025 rather than ones arriving later.

Practically it needs legal, product and security together, because the scope test is legal, the transparency duties are product engineering, and the inventory is usually security or IT. A single owner without those three is unable to close the work.

We scope by the number of AI systems and how many are in scope once the output test is applied. The free first step: list every AI system you operate and write down where its output is used. That column answers the scope question.

Broadly, a provider places a system on the market or puts it into service, and a deployer uses one. The Act assigns different obligations to each, and a single organisation is frequently both across different systems in its portfolio.

Article 2 refers to authorised representatives of providers not established in the Union, which indicates the concept applies to third country providers in defined circumstances. Whether it applies to you is a legal question worth resolving early.

Answer with specifics. Which systems, whether the output is used in the Union, the result of the prohibition screening, your role for each system, and the transparency measures implemented. A general assurance of compliance invites the follow up question.

It is targeted rather than general. The obligation concerns staff and others dealing with the operation and use of AI systems on your behalf, taking account of their knowledge, the context of use, and the people the systems are used on.

Only where a prohibited practice is involved, and that is a screening question you can answer in days. For everything else the sensible path is continued use with the scope, role and transparency work running alongside it.
Two dates have already passed

The staged timeline means part of this is a present obligation, not a 2026 project.

Organisations reading about the general application date frequently conclude they have time, and for two significant chapters they do not.

  • Chapters I and II applied from 2 February 2025. That covers the prohibited practices and the AI literacy obligation, both of which are in force now. An organisation operating a prohibited practice is not approaching a deadline, it is past one.
  • General-purpose AI and governance provisions applied from 2 August 2025, excluding the Article 101 penalties. Organisations building on or providing general-purpose models have been inside that scope for some time already.
  • The general application date of 2 August 2026 covers the bulk of the Regulation, including the transparency duties in Article 50. That is the date most planning is built around, and it is the third milestone rather than the first.
  • The Article 6(1) high-risk classification rules apply from 2 August 2027. That later date is why high-risk assessment can be planned rather than rushed, provided the prohibition screening and the literacy obligation have already been addressed.
Related reading

The pages around this one.

AI governance framework

The voluntary framework that makes compliance easier.

Learn more

GDPR for UAE businesses

The other EU instrument with extraterritorial reach.

Learn more

UAE PDPL compliance

The domestic personal data position.

Learn more
Next step

List every AI system you operate, and write down where its output is used.

Any answer involving the Union puts that system inside a scope question. Then screen those systems against the eight prohibited practices, which have applied since February 2025.

Book an AI Act exposure reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

AI governance framework

Know what AI is in use, and who approved it.

Learn more

GDPR for UAE Businesses

When EU law actually reaches a UAE business, and when it does not

Learn more

UAE PDPL Compliance

Federal Decree-Law 45 of 2021 readiness and operations

Learn more

Privacy Impact Assessment

DPIA done at design stage, necessity tested properly

Learn more

IT Risk Assessment

A short register with an owner against every risk

Learn more

Compliance as a Service

Keeping the position true between assessments

Learn more

Virtual CISO Dubai

Security governance and accountability, not more tools

Learn more

Security Policy Development

Policies you can actually comply with

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy